Russia-aligned Gamaredon significantly upgraded its cyberespionage operations against Ukrainian government and military organizations during 2025, according to ESET. The group ran 35 spear-phishing campaigns, introduced six new PowerShell-based tools, revived the VBScript weaponizer PteroSetup, and exploited CVE-2025-8088 in WinRAR to establish persistence through malicious HTA downloaders placed in Startup folders. ESET said Gamaredon also expanded lateral movement and USB-based propagation, with the newly documented PteroPaste able to copy a malicious downloader to connected USB drives while disguising it as a Word document shortcut.
The group increasingly concealed command-and-control and data theft behind legitimate services, using Cloudflare Workers, Microsoft dev tunnels, Loophole, DDNS providers, messaging and blogging platforms, paste sites, and cloud storage to mask malicious traffic and stage payloads. Newer malware variants retrieved encrypted C2 data from dead-drop locations such as Telegram, Dropbox, GoFile, and Mastodon, while upgraded stealers including PteroPSDoor and PteroVDoor exfiltrated stolen files to S3-compatible storage such as Wasabi, Tebi, and Intercolo. ESET also observed Gamaredon collaborating with Turla in early 2025, providing initial access that supported deployment of the Kazuar framework.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Gurucul's threat research report released a detailed IOC set for Gamaredon's 2025 activity, including domains, URLs, three IP addresses, and 22 SHA-1 hashes. The report also provided Gurucul TDIR detection queries to help identify related malicious activity.
By December 2025, Intercolo had become the primary S3-compatible destination for Gamaredon's stolen-data exfiltration. This marked the latest observed shift in the group's cloud-based exfiltration infrastructure.
During 2025, Gamaredon updated malware including PteroPSDoor and PteroVDoor to exfiltrate stolen files to S3-compatible cloud storage providers. Reported destinations shifted from Wasabi to Tebi and later to Intercolo as the group blended malicious traffic with legitimate cloud usage.
In the second half of 2025, Gamaredon escalated its operations with at least 35 spear-phishing campaigns. Reporting says these upgrades enabled larger attacks focused exclusively on Ukrainian governmental and military institutions.
ESET documented PteroPaste as a new and more complex Gamaredon tool that combines downloader, USB weaponization, and runner functions. It can copy a malicious downloader to connected USB drives disguised as a Word document shortcut and use Dropbox in its workflow.
A major trend during 2025 was Gamaredon's expanded use of legitimate third-party services to hide command-and-control infrastructure and stage payloads. Reported services included Cloudflare Workers, Microsoft dev tunnels, Loophole, DDNS, messaging platforms, blogging sites, paste services, and cloud storage.
In 2025, Gamaredon started exploiting CVE-2025-8088 in WinRAR to gain persistence, including use of malicious HTA downloaders placed in Startup folders. The vulnerability became part of the group's infection and persistence chain.
In 2025, Gamaredon revived its older VBScript weaponizer PteroSetup and expanded lateral-movement capabilities with multiple weaponizers. These changes formed part of a broader refresh of the group's tooling.
During the first half of 2025, Gamaredon developed six new PowerShell-based tools and expanded its malware toolkit. The additions supported the group's continued cyberespionage operations against Ukrainian government and military targets.
ESET observed Gamaredon working with the Russian APT Turla in early 2025, with reporting indicating Gamaredon provided initial access to support deployment of Turla's Kazuar framework. This was cited as evidence of coordination among Russia-aligned threat actors.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourcecommunity.gurucul.com
Open sourcegovinfosecurity.com
Open sourcedarkreading.com
Open sourcewelivesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.